LiveActive security incident?Get immediate response
CVE archive

2002 CVE Archive

Browse CVE records published in 2002 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2357 matching CVEs · Page 20 of 48.

Unknown · CVSS Not scored

CVE-2002-1486: Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC server...

Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.

Published Mar 18, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-1484: DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a pr...

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

Published Mar 18, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-1476: Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, whe...

Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the boundaries of the new_categories category array, as exploitable through programs such as xterm and zsh.

Published Sep 1, 2004 · Updated Aug 8, 2024